Transfer authority without sharing passwords
List services the club owns: email, domain, website, membership system, payment provider, bank, social accounts, storage and insurance. Use each service's official role-transfer or recovery process; never put a shared password or MFA recovery code in meeting minutes.
For every tool, name an incoming owner and a second authorised officer. Update recovery contacts to club-controlled addresses and record the effective date. Then remove the former officer's access after the agreed overlap.
- Use named accounts and least-privilege roles where offered.
- Review connected devices and API/app access as well as named users.
- Ask a second officer to confirm the removal and recovery setup.